Sign inSign up
Thanos

dhi.io/thanos

Thanos 0.42.x

CIS
linux/amd64
alpine 3.24
Tags:

0-alpine, 0-alpine3.24, 0.42-alpine, 0.42-alpine3.24, 0.42.4-alpine, 0.42.4-alpine3.24

Index digest:

sha256:8f1a595bc4983c7e1f855bfdbad0a48ffbb377a1ef64aad5c9f73f26ce2b074d

Manifest digest:

sha256:bcd41c0830787e85f7db28a2f34e933cd7b0b665bdccb87dc05a420cf61b9f08

Size

27.17 MB

Last pushed

1 day ago

Vulnerabilities

0
0
0
1
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/thanos:0-alpine

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/thanos:0-alpine --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/thanos@sha256:07368c87d36d435b865f442d86f3b564a34eae34f52e73a77b39a83019a4f213
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/thanos@sha256:41151331175b4a924dfd4aa8e1cb9167c92947ea76fca4053a8bbd4a23a0cc17
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/thanos@sha256:b0ef7ca585b6f46466ce1c5b13fac4f3826b6e40097a0ae478252b31e5a6f1c4
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/thanos@sha256:29b6ac0f89804c468b16bfe57402950dc30471cfe93cac2419c81e4aaba8c901
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/thanos@sha256:caa969e31dfa8f33b3e442b3e3ed8a4416631527015eb4b6a94a71d09ab6cdcb
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/thanos@sha256:42c406066dd2904426981ccc9dcf6cf87eb4df661fc8fcc98623351334bf2e34
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/thanos@sha256:a6fb6fbbac2ca16ff7d50b237a439f22ec00ce16e4813afa055bd248fd741ab4
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/thanos@sha256:f6c78e7e95e2a4cd16355ab61af79a9c98940789b9203a64463daf3eeb158e80
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/thanos@sha256:4be069d01837b766e7dbebaa69a2bf6c6324a4421d221a9a7a0def77bfad7841
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/thanos@sha256:e9143f7a83853471a7b0fd54d46e5287e2faf46a98a78b96f9bb62895a9e6d70
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/thanos@sha256:069790c2828e058c46b0fa0f537807f01bcf4c783a333cfec670d1e4e7a68253
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/thanos@sha256:e37278066cc11d5bca19c5b5e7ed33a2de42b4d0888cd372c635156906768780
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/thanos@sha256:0320f7a70de347959d5da85bb4fff484afb36868173e14b39b67bb82beb8b95e
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/thanos@sha256:605f863eddb98d72824ec91074eed74f4b36b8352e106e07e16d0eb49fd181c1
SPDX SBOMhttps://spdx.dev/Documentdhi.io/thanos@sha256:5c3f4f7489f58c417e6a5e7450c4511aee6794bc161fd104f8499cff72e5453f